2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-39308MEDIUM6.1The WooCommerce myghpay Payment Gateway WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the clientre...
CVE-2021-38361MEDIUM6.1The .htaccess Redirect WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the link parameter found in ...
CVE-2021-38182HIGH8.8Due to insufficient input validation of Kyma, authenticated users can pass a Header of their choice and escalate privile...
CVE-2021-4107MEDIUM6.1yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4007HIGH7.8Rapid7 Insight Agent, versions 3.0.1 to 3.1.2.34, suffer from a local privilege escalation due to an uncontrolled DLL se...
CVE-2021-44949CRITICAL9.8glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.
CVE-2021-42051MEDIUM5.4An issue was discovered in AbanteCart before 1.3.2. Any low-privileged user with file-upload permissions can upload a ma...
CVE-2021-42050MEDIUM6.1An issue was discovered in AbanteCart before 1.3.2. It allows DOM Based XSS.
CVE-2021-45015CRITICAL9.1taocms 3.0.2 is vulnerable to arbitrary file deletion via taocms\include\Model\file.php from line 60 to line 72.
CVE-2021-45014CRITICAL9.8There is an upload sql injection vulnerability in the background of taocms 3.0.2 in parameter id:action=cms&ctrl=update&...
CVE-2021-44538CRITICAL9.8The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session obje...
CVE-2021-3376HIGH8.8An issue was discovered in Cuppa CMS Versions Before 31 Jan 2021 allows authenticated attackers to gain escalated privil...
CVE-2021-36721MEDIUM5.3Sysaid API User Enumeration - Attacker sending requests to specific api path without any authorization before 21.3.60 ve...
CVE-2021-44937MEDIUM5.3glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php. An attacker c...
CVE-2021-44935CRITICAL9.1glFusion CMS v1.7.9 is affected by an arbitrary user impersonation vulnerability in /public_html/comment.php. The attack...
CVE-2021-4104HIGH7.5JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Lo...
CVE-2021-44524CRITICAL9.8A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), S...
CVE-2021-44523CRITICAL9.1A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), S...
CVE-2021-44522HIGH7.5A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), S...
CVE-2021-44450HIGH7.8A vulnerability has been identified in JT Utilities (All versions < V12.8.1.1), JTTK (All versions < V10.8.1.1). JTTK li...
CVE-2021-44449HIGH7.8A vulnerability has been identified in JT Utilities (All versions < V12.8.1.1), JTTK (All versions < V10.8.1.1). JTTK li...
CVE-2021-44448LOW3.3A vulnerability has been identified in JT Utilities (All versions < V13.0.3.0), JTTK (All versions < V11.0.3.0). JTTK li...
CVE-2021-44447HIGH7.8A vulnerability has been identified in JT Utilities (All versions < V13.0.3.0), JTTK (All versions < V11.0.3.0). JTTK li...
CVE-2021-44446HIGH7.8A vulnerability has been identified in JT Utilities (All versions < V13.0.3.0), JTTK (All versions < V11.0.3.0). JTTK li...
CVE-2021-44445HIGH7.8A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK li...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now